Job Search, Job Listing, Opportunity
Work at home job, job vacancy
find a job, vacancy list, cari lowongan
Butuh, Segera, secretary, director

SMURF attack mitigation features…


All, I’m curious as to what SMURF attack mitigation features there are… If I am correct in my understanding of a SMURF attack it is set up as follows:
The attacker is on a remote segment using a directed broadcast at a target on your LAN segment
How can we mitigate these attacks?
What I’m aware of (please tell me if I’m off-base or should be doing more/less)…
-Enable unicast RPF on your WAN interface (stops receiving fake source addresses) -No ip directed-broadcast under your LAN interface (stops sending off-network broadcasts) -Put an ACL on the WAN interface that does a ‘log-input’ on the end or also ip source-track (lets you figure out where your attacker is)
What is the difference between ip source-track and doing a permit ip any any log-input in an ACL?
Thanks in advance!!! — Tony Paterra apaterra@gmail.com

Bookmark this post:These icons link to social bookmarking sites where readers can share and discover new web pages.
  • blinkbits
  • BlinkList
  • blogmarks
  • co.mments
  • connotea
  • del.icio.us
  • De.lirio.us
  • digg
  • Fark
  • feedmelinks
  • Furl
  • LinkaGoGo
  • Ma.gnolia
  • NewsVine
  • Netvouz
  • RawSugar
  • Reddit
  • scuttle
  • Shadows
  • Simpy
  • Smarking
  • Spurl
  • TailRank
  • Wists
  • YahooMyWeb
keywords found: unicast sending where remote using target aware 

Leave a Comment

Related Post